HPE FlexNetwork 10500 Series Security Configuration Manual page 11

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Main mode IKE with pre-shared key authentication configuration example··········································· 369
Aggressive mode with RSA signature authentication configuration example ········································ 371
Troubleshooting IKE······································································································································· 375
IKE negotiation failed because no matching IKE proposals were found ················································ 375
IPsec SA negotiation failed because no matching IPsec transform sets were found ···························· 376
IPsec SA negotiation failed due to invalid identity information ······························································· 377
Configuring IKEv2 ······················································································ 380
Overview ························································································································································ 380
IKEv2 negotiation process ····················································································································· 380
New features in IKEv2 ···························································································································· 381
Protocols and standards ························································································································ 381
IKEv2 configuration task list ··························································································································· 381
Configuring an IKEv2 profile ·························································································································· 382
Configuring an IKEv2 policy ··························································································································· 385
Configuring an IKEv2 proposal ······················································································································ 386
Configuring an IKEv2 keychain ······················································································································ 387
Configure global IKEv2 parameters ··············································································································· 388
Enabling the cookie challenging feature ································································································ 388
Configuring the IKEv2 DPD feature ······································································································· 388
Configuring the IKEv2 NAT keepalive feature ························································································ 389
Configuring IKEv2 address pools ··········································································································· 389
Displaying and maintaining IKEv2·················································································································· 389
IKEv2 configuration examples ······················································································································· 390
IKEv2 with pre-shared key authentication configuration example ·························································· 390
IKEv2 with RSA signature authentication configuration example ·························································· 393
Troubleshooting IKEv2 ··································································································································· 397
IKEv2 negotiation failed because no matching IKEv2 proposals were found ········································ 397
IPsec SA negotiation failed because no matching IPsec transform sets were found ···························· 398
IPsec tunnel establishment failed ··········································································································· 398
Configuring SSH ························································································ 399
Overview ························································································································································ 399
How SSH works ····································································································································· 399
SSH authentication methods ·················································································································· 400
SSH support for Suite B ························································································································· 401
FIPS compliance ············································································································································ 401
Configuring the device as an SSH server ······································································································ 402
SSH server configuration task list ·········································································································· 402
Generating local key pairs ······················································································································ 402
Enabling the Stelnet server ···················································································································· 403
Enabling the SFTP server ······················································································································ 403
Enabling the SCP server ························································································································ 404
Enabling NETCONF over SSH ·············································································································· 404
Configuring the user lines for SSH login ································································································ 404
Configuring a client's host public key ····································································································· 405
Configuring an SSH user ······················································································································· 406
Configuring the SSH management parameters ····················································································· 407
Specifying a PKI domain for the SSH server ························································································· 408
Specifying the SSH service port ············································································································· 408
Disconnecting SSH sessions ················································································································· 409
Configuring the device as an Stelnet client ···································································································· 409
Stelnet client configuration task list ········································································································ 409
Generating local key pairs ······················································································································ 409
Specifying the source IP address for SSH packets················································································ 410
Establishing a connection to an Stelnet server ······················································································ 410
Deleting server public keys saved in the public key file on the Stelnet client········································· 412
Establishing a connection to an Stelnet server based on Suite B ·························································· 413
Configuring the device as an SFTP client ······································································································ 413
SFTP client configuration task list ·········································································································· 413
Generating local key pairs ······················································································································ 414
ix

Advertisement

Table of Contents
loading

Table of Contents